This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:todd_miller:sudo:1.6.4p1 |
| Detail | |||
|---|---|---|---|
| Vendor | Todd_Miller | First view | 2002-05-16 |
| Product | Sudo | Last view | 2011-01-20 |
| Version | 1.6.4p1 | Type | Application |
| Edition | |||
| Language | |||
| Update | |||
| CPE Product | cpe:/a:todd_miller:sudo | ||
Activity : Yearly
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 6.9 | 2011-01-20 | CVE-2011-0008 | Local | Medium | None Requ... | |
| 6.2 | 2010-06-07 | CVE-2010-1646 | Local | High | None Requ... | |
| 6.2 | 2007-08-13 | CVE-2007-4305 | Local | High | None Requ... | |
| 4.6 | 2005-10-25 | CVE-2005-2959 | Local | Low | None Requ... | |
| 7.2 | 2002-05-16 | CVE-2002-0184 | Local | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 100% (2) | CWE-264 | Permissions, Privileges, and Access Controls |
CAPEC : Common Attack Pattern Enumeration & Classificatio
| id | Name |
|---|---|
| CAPEC-3 | Using Leading 'Ghost' Character Sequences to Bypass Input Filters |
| CAPEC-6 | Argument Injection |
| CAPEC-15 | Command Delimiters |
| CAPEC-18 | Embedding Scripts in Nonscript Elements |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
| id | Name |
|---|---|
| CAPEC-47 | Buffer Overflow via Parameter Expansion |
| CAPEC-63 | Simple Script Injection |
| CAPEC-71 | Using Unicode Encoding to Bypass Validation Logic |
| CAPEC-73 | User-Controlled Filename |
| CAPEC-85 | Client Network Footprinting (using AJAX/XSS) |
| CAPEC-86 | Embedding Script (XSS ) in HTTP Headers |
| CAPEC-100 | Overflow Buffers |
| CAPEC-123 | Buffer Attacks |
| CAPEC-163 | Spear Phishing |
Oval Markup Language : Definitions
| OvalID | Name |
|---|---|
| oval:org.mitre.oval:def:7338 | VMware ESX, Service Console update for sudo. |
| oval:org.mitre.oval:def:10580 | The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 thr... |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 65083 | sudo env.c secure path Restrictions Bypass Arbitrary File Execution |
| 51736 | sudo parse.c System Group Interpretation Local Privilege Escalation |
| 39589 | Multiple BSD Systrace Sysjail Policies Race Condition Access Control Policy B... |
| 39588 | Multiple BSD Sudo Monitor Mode Race Condition Access Control Policy Bypass |
| 20303 | Sudo Environment Variable Manipulation Local Privilege Escalation |
| id | Description |
|---|---|
| 5344 | sudo -p Option Local Overflow |










